GHSA-36xx-7vf6-7mv3

    Dashboard / Vulnerabilities / GHSA-36xx-7vf6-7mv3

    GHSA-36xx-7vf6-7mv3

    Published: 31 Jul 2023Last Modified: 16 Feb 2024

    Summary: Silverstripe Framework: Members with no password can be created and bypass custom login forms

    Details: When a new `Member` record was created in the cms it was possible to set a blank password. If an attacker knows the email address of the user with the blank password then they can attempt to log in using an empty password. The default member authenticator, login form and basic auth all require a non-empty password, however if a custom authentication method is used it may allow a successful login with the empty password. Starting with this release, blank passwords are no no longer allowed when members are created in the CMS. Programatically created `Member` records, such as those used in unit tests, still allow blank passwords. You may have some `Member` records in your system already which have empty passwords. To detect these, you can loop over all `Member` records with `Member::get()` and pass each record into the below method. It might be sensible to create a [`BuildTask`](https://api.silverstripe.org/5/SilverStripe/Dev/BuildTask.html) for this purpose. ```php private function memberHasBlankPassword(Member $member): bool { // skip default admin as this is created programatically if ($member->isDefaultAdmin()) { return false; } // return true if a blank password is valid for this member $authenticator = new MemberAuthenticator(); return $authenticator->checkPassword($member, '')->isValid(); } ``` Once you have identified the records with empty passwords, it's up to you how to handle this. The most sensible way to resolve this is probably to generate a new secure password for each of these members, mark it as immediately expired, and email each affected member (assuming they have a valid email address in the system). Users would need to opt-in to insecure behavior by using a configuration which allowed for empty passwords. These configurations are not expected and hence this advisory is primarily informational in nature. Reported by: [Sabina Talipova](https://www.silverstripe.com/about-us/team/?member=sabina-talipova) from Silverstripe and [Christian Bünte](https://github.com/bimthebam)

    Affected packages

    Package

    Name: silverstripe/framework

    Purl: pkg:composer/silverstripe/framework

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 3.0.0
    Fixed -4.13.14

    Affected versions

    3.0.10
    3.0.10-rc1
    3.0.11
    3.0.11-rc1
    3.0.12
    3.0.13
    3.0.14
    3.0.2.1
    3.0.3
    3.0.3-rc1
    3.0.3-rc2
    3.0.4
    3.0.5
    3.0.6
    3.0.6-rc1
    3.0.6-rc2
    3.0.7
    3.0.7-rc1
    3.0.8
    3.0.9
    3.0.9-rc1

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-36xx-7vf6-7mv3 | CVE-DB